Vulnerability Name: | CVE-2007-2398 (CCN-35050) | ||||||||
Assigned: | 2007-06-21 | ||||||||
Published: | 2007-06-21 | ||||||||
Updated: | 2018-10-16 | ||||||||
Summary: | Apple Safari 3.0.1 beta (522.12.12) on Windows allows remote attackers to modify the window title and address bar while filling the main window with arbitrary content by setting the location bar and using setTimeout() to create an event that modifies the window content, which could facilitate phishing attacks. | ||||||||
CVSS v3 Severity: | 3.7 Low (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||
CVSS v2 Severity: | 7.1 High (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:C/A:N) 5.3 Medium (Temporal CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:C/A:N/E:U/RL:OF/RC:C)
1.9 Low (CCN Temporal CVSS v2 Vector: AV:N/AC:H/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||
Vulnerability Type: | CWE-Other | ||||||||
Vulnerability Consequences: | Gain Access | ||||||||
References: | Source: FULLDISC Type: UNKNOWN 20070614 Re: Apple Safari: urlbar/window title spoofing Source: MITRE Type: CNA CVE-2007-2398 Source: APPLE Type: UNKNOWN APPLE-SA-2007-06-22 Source: CCN Type: APPLE-SA-2007-06-22 Safari 3 Beta Update 3.0.2 Source: APPLE Type: UNKNOWN APPLE-SA-2008-04-16 Source: CCN Type: APPLE-SA-2008-04-1 APPLE-SA-2008-04-16 Safari 3.1.1 Source: OSVDB Type: UNKNOWN 38862 Source: CCN Type: SECTRACK ID: 1018282 Apple Safar Bugs Let Remote Users Modify the Address Bar and Conduct Cross-Domain Scripting Attacks Source: CONFIRM Type: UNKNOWN http://support.apple.com/kb/HT1467 Source: CCN Type: Apple Safari Web site Apple - Safari 3 Public Beta Source: CCN Type: OSVDB ID: 38862 Apple Safari Location Bar setTimeout() Content Spoofing Source: BUGTRAQ Type: UNKNOWN 20070614 Re: [Full-disclosure] Apple Safari: urlbar/window title spoofing Source: BUGTRAQ Type: UNKNOWN 20070615 Re: [Full-disclosure] Apple Safari: urlbar/window title spoofing Source: BID Type: UNKNOWN 24484 Source: CCN Type: BID-24484 Apple Safari for Windows Content and URLBar Spoofing Vulnerability Source: SECTRACK Type: UNKNOWN 1018282 Source: VUPEN Type: UNKNOWN ADV-2007-2316 Source: VUPEN Type: UNKNOWN ADV-2008-0979 Source: XF Type: UNKNOWN safari-addressbar-spoofing(35050) Source: XF Type: UNKNOWN safari-addressbar-spoofing(35050) | ||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: Denotes that component is vulnerable | ||||||||
BACK |